New! Claude now connects directly to Lusha’s verified B2B data
New! Claude now connects directly to Lusha’s verified B2B data

Connect now

Connect now

A plain answer to the question procurement asks first: what Lusha is certified for, who audited it, where the data comes from, and what anyone in the database can do about it.

Yes. Lusha’s GDPR compliance is certified by ePrivacyseal GmbH, a European independent auditor, and its CCPA compliance is validated by TrustArc. Lusha holds SOC 2 Type II, ISO 27001, ISO 27017, ISO 27701, ISO 31700 and ISO 42001, and TRUSTe Responsible AI certification. It is registered with the California Data Broker Registry, collects business contact information only, and gives anyone whose details are in the database the right to see, correct or remove them. Certificates, the Data Processing Agreement, Standard Contractual Clauses and the subprocessor list are on the Trust Center.

Key takeaways

  • Certified, not self-declared. GDPR by ePrivacyseal GmbH, CCPA by TrustArc, information security and privacy by accredited ISO auditors, SOC 2 Type II by an independent auditor.
  • Business contact data only. Name, title, work email, business phone, company. The kind of information on a business card. No consumer data, no scraping of social networks.
  • Rights built in. Opt-out and Do Not Sell links in every footer, Article 14 notifications, automated handling of access and deletion requests, a Do Not Call flag on every phone record.
  • Your own obligations still apply. Lusha’s compliance covers how the data is collected and processed. Your outreach has its own legal basis, and the compliance guide walks through it.

Is Lusha GDPR compliant?

Yes. Lusha’s GDPR compliance is certified by ePrivacyseal GmbH. In practice that covers: a Data Processing Agreement available to every customer, Standard Contractual Clauses for transfers outside the EU, Legitimate Interest Assessments conducted and documented for the processing of business contact data, Data Protection Impact Assessments available on request, Article 14 notification mechanisms so individuals learn their business details are in the database, and automated handling of data subject requests for access, correction and deletion. Personal data of EU customers is stored mainly in EU regions. Lusha also holds ISO 27701, the privacy information management extension to ISO 27001, which is the standard most closely mapped to GDPR controls.

Is Lusha CCPA compliant?

Yes. Lusha’s CCPA and CPRA compliance is validated by TrustArc. That covers Do Not Sell mechanisms and opt-out support, processing of consumer rights requests for access, deletion and opt-out, transparency about what is collected, how it is used and with whom it is shared, and service provider agreements that meet CCPA standards. Lusha is registered with the California Data Broker Registry, which is the public register California requires of any business that sells personal information it did not collect directly from the consumer. US data is stored in US regions.

Which certifications does Lusha hold?

CertificationWhat it coversWho audited it
SOC 2 Type IISecurity, availability, confidentiality and privacy controls, tested over a periodIndependent auditor; report available under gated access
ISO 27001Information security management systemAccredited third party, ANAB vetted
ISO 27017Cloud-specific security controls on top of 27001Accredited third party
ISO 27701Privacy information management, the GDPR-aligned extension to 27001Accredited third party
ISO 31700Privacy by design for consumer goods and servicesAccredited third party
ISO 42001AI management system, governance of AI capabilitiesAccredited third party
TRUSTe Responsible AIData governance alignment with ethical standards and regulation for AITRUSTe
GDPRCertified complianceePrivacyseal GmbH
CCPA / CPRAValidated complianceTrustArc


Source: Lusha Trust Center, compliance page, accessed October 7, 2026.

Every certificate, in one place

SOC 2 report, ISO certificates, DPA, SCCs, subprocessor list and whitepapers, available for download or on request.

Open the Trust Center

Where does Lusha’s data come from?

Four sources, described on the data sources page. Members of the Lusha Community, who opt in and share business contact details from email headers and signatures. Licensed partners with established business directories, each vetted for security and GDPR and CCPA compliance. Publicly available business information. And Lusha’s own analysis, which completes patterns such as company email formats. Lusha does not scrape professional networks or social platforms and does not buy from data brokers. The data is business contact information: name, title, company, work email, business phone.

Is Lusha a data broker?

Under California’s definition, yes, and it is registered as one. The California Data Broker Registry lists businesses that sell personal information they did not collect directly from the individual. Registration is what puts a business under the state’s transparency and deletion requirements, which is the point of the register. Lusha’s listing, its Do Not Sell mechanism and its removal form are the practical result.

Where is Lusha’s data stored?

Personal data of EU customers is stored mainly in EU regions. US data is stored in US regions. Cross-border transfers use Standard Contractual Clauses, with Transfer Impact Assessments conducted and data flows documented. The Transfer Impact Assessment is linked in the site footer.

How do I remove my information from Lusha?

Through the removal request form, also linked as Opt Out and Do Not Sell My Info in the footer of every page. Once processed, the record is added to a suppression list and Lusha notifies customers who previously received it. The same Privacy Center lets anyone view and correct their information. Lusha also sends Article 14 notifications where the law requires, so people learn their business details are in the database before a customer uses them.

Does Lusha show Do Not Call status?

Yes. Every phone record carries a Do Not Call flag, returned as a field through the Workspace, the API and the MCP, so a rep knows before dialing and a dialer can suppress flagged numbers automatically. US mobile numbers carry TCPA obligations; the flag helps, and your own obligations still apply.

Which compliance documents can I get?

Available for download or on request from the Trust Center: the SOC 2 Type II report (gated), ISO certificates, the Data Processing Agreement, Standard Contractual Clauses, the subprocessor list, the security whitepaper, the privacy whitepaper, and a penetration test summary under NDA. The Trust Kit keeps the current set of third-party audits and certifications in one place.

Is Lusha a GDPR-friendly choice for outreach in Europe?

Yes, with one condition. Lusha’s certification covers how the data is collected and processed. Your outreach has its own legal basis under GDPR, which you document for your own processing. The compliance guide in the Knowledge Hub walks through how to do that with Lusha data, and every phone record’s Do Not Call status is part of the answer. For how other vendors compare on compliance, see Best privacy compliant B2B data providers in the US.

Verified data, with the paperwork to match

Business contact data only, certified under GDPR and CCPA, with a Do Not Call flag on every number.

Start for free

FAQ

Is Lusha GDPR compliant?

Yes. Certified by ePrivacyseal GmbH, with a DPA, SCCs, documented Legitimate Interest Assessments, Article 14 notifications and automated data subject request handling. Lusha also holds ISO 27701.

Is Lusha CCPA compliant?

Yes. Validated by TrustArc, with Do Not Sell mechanisms, consumer rights request processing and registration with the California Data Broker Registry.

Which ISO certifications does Lusha hold?

ISO 27001, 27017, 27701, 31700 and 42001, all audited by accredited third parties. Plus SOC 2 Type II and TRUSTe Responsible AI.

Does Lusha collect personal data?

Business contact information only: name, title, company, work email and business phone. No consumer data, no scraping of social networks.

How do I opt out of Lusha?

Through the removal request form, linked as Opt Out and Do Not Sell My Info in every page footer. The record goes on a suppression list and customers who received it are notified.

Can I use Lusha data for outreach in the EU?

Yes. Lusha’s certification covers how the data is collected and processed. Your outreach needs its own documented legal basis, and the compliance guide covers that side.

Sources